FEATURES, COMPATIBILITY & PRIVACY

Know what connects.
Know what is supported.

A practical guide to sec·o·sync: services, VPN engines, authenticators, system integration and the limits that matter.

What is available on each platform

Android is the documented product baseline: account setup, system calendar/contact integration, private tasks and mail workspaces, reusable VPNs and authenticators, protected settings, backups and activity history. Broad physical-device and live-server qualification is still incomplete.

The iOS project has a shared-core integration and EventKit/Contacts mirror foundation, but not the same implemented product surface. EWS is not implemented on iOS. OpenConnect requires an additional reviewed iOS SDK; native build verification and store acceptance are not established by these documents. Do not read the two store buttons as a promise of equivalent releases.

System accounts, calendars and contacts

On Android, accounts are registered with AccountManager and synchronized using service-specific SyncAdapters. Selected calendars and address books are available through Calendar Provider and Contacts Provider, so other compatible, permitted apps can use them.

Tasks use a separate encrypted, app-private store and task SyncAdapter; they are not disguised as calendar events. Mail also uses app-private metadata, body-cache and outbox stores. There is no claim that arbitrary mail or task apps can consume these as universal system accounts.

Calendar/contact permissions are requested for the selected resources. Their system-provider copies follow Android permissions and device security. A settings lock or whole-app lock in sec·o·sync does not block another permitted app from reading those provider copies.

Services and supported data

Each calendar, address book, task list or mail service is a target with its own enabled state, credentials, connection policy and schedule. Support below is bounded: unsupported object shapes may remain read-only or be omitted with diagnostics rather than silently rewritten.

On a narrow screen, scroll the table sideways.

Documented service coverage
ServiceWhat is implementedImportant boundary
CalDAV calendarsDiscovery, selected collections, calendar sync and bounded editing through Android Calendar Provider.Complex recurrence, scheduling and unsupported fields are subject to explicit fidelity and write-safety limits.
CardDAV contactsDiscovery, selected address books, Android Contacts integration and bounded structured contact editing.Not every vCard extension, group or photo shape is editable.
CalDAV tasks (VTODO)A separate task workspace, private encrypted store and bounded two-way task synchronization.Tasks are not VEVENT calendar rows; richer task and recurrence shapes can remain read-only.
IMAP / POP3 + SMTPMail metadata sync; explicit IMAP message loading; bounded MIME views, reply/compose and an encrypted SMTP outbox.POP3 is download-only. This is a bounded mail workspace, not a claim of a complete mail client or universal server compatibility.
On-premises Exchange EWS — experimentalSelected calendars, ordinary contact folders and a conservative TasksFolder adapter.Android only. Exchange mail is separately configured IMAP/POP3 + SMTP, not EWS mail synchronization. Not Exchange Online.
Microsoft 365 / Graph — unavailableInternal interfaces and a read-only To Do foundation exist.Production adapters remain disabled. Do not advertise Microsoft 365 synchronization.
JMAP — library foundation onlyBounded, read-only Go library components.No shipped Android account, schedule, storage or UI integration.

Open-source VPN engines and open standards

The app uses existing open-source VPN implementations rather than describing a proprietary security algorithm. OpenConnect and OpenVPN 3 are engines, not VPN subscriptions. CalDAV and CardDAV are open synchronization standards. Use of open-source components is not, by itself, an independent audit of the finished app.

On a narrow screen, scroll the table sideways.

VPN and provisioning status
TechnologyDocumented statusScope / limitation
WireGuard / wireguard-goImplemented userspace data path.App-private transport with an in-memory networking stack; gateway and device testing still matter.
OpenVPN 3Android native build/package baseline.OpenVPN client engine with external-TUN integration; packaged code is not proof of all-gateway interoperability. iOS pipeline remains unverified.
OpenConnect / libopenconnectAndroid native build/package baseline.Vendor-compatible modes depend on the installed build and gateway authentication. iOS requires an additional reviewed SDK.
IKEv2/IPsecExperimental userspace implementation.EAP-MSCHAPv2 or PSK; optional explicit password/TOTP composition. No EAP-TLS or general multi-round EAP MFA.
eduVPNWireGuard and OpenVPN provisioning implemented.A provider/setup flow that obtains a compatible profile, not a separate tunnel protocol.

The OpenConnect family includes AnyConnect, Juniper Network Connect, Pulse, GlobalProtect, Fortinet, F5 and Array protocol modes upstream. The app must expose only engines/modes included in its build. Neither that list nor an upstream compatibility claim establishes a tested sec·o·sync gateway combination. Device-posture checks, proprietary login forms and organizational policy can still prevent a connection.

Check first, require a VPN, or never open one

Connection decisions belong to the individual sync target. Accounts can reference different reusable VPN profiles; operations sharing the same selected profile can reuse an app-owned connection.

On a narrow screen, scroll the table sideways.

Per-target connection policy
PolicyWhat happens
Direct onlyUse the route already available. Never acquire an app-managed VPN. That route may already pass through a system VPN.
Direct, then tunnel (“check first”)Check the intended service through the current route. Use the assigned tunnel only for an eligible connectivity failure.
Tunnel onlyRequire the assigned app-managed tunnel. Skip the direct-route check; being reachable directly does not override the policy.

“Reachable” is not “safe to use regardless of policy.” Certificate, TLS, authentication and protocol failures are not treated as permission to bypass a requirement or to weaken validation.

Existing system VPNs are respected when they route this app. An inner app-owned tunnel can travel through the outer connection if the outer VPN permits it. This is not several simultaneous Android VpnService instances and it does not alter device-wide routes or carry arbitrary traffic from other apps.

Connection release is coordinated with active users. New profiles default to 30 seconds minimum connection time and 15 seconds idle grace; either setting can be configured from 0 to 900 seconds. Related work reuses the connection. Explicit disconnect cannot interrupt other active users. No claim is made that a tunnel always closes immediately after a single sync.

Dashboard, hidden sections and quick views

Configure dashboard widgets and hide or collapse unneeded sections. VPNs, accounts and issues have their own status surfaces; the interface offers light, dark and system-following themes.

Calendar, Contacts, Tasks and Mail workspaces offer source selection and quick views. The calendar has month/week/day/agenda views; tasks have source and due-state filters; contacts have lists and bounded editors. Mail starts from cached headers. Message content is loaded explicitly and stored in a bounded encrypted cache; opening a list does not fetch every body.

Authenticator widgets retain protected reveal/copy and countdown behavior. These are in-app dashboard widgets, not a claim of an Android home-screen widget. Hiding a section is a display choice, not a way to disable synchronization or remove a permission.

Authenticators and multifactor sign-in

Android exposes reusable TOTP authenticators. Add a Base32 secret manually, scan a standard otpauth://totp QR code with the optional camera flow, or select an image for local decoding. Review the fields before saving. QR frames and decoded payloads are not uploaded.

On a narrow screen, scroll the table sideways.

Authentication coverage
MechanismStatus / behavior
TOTP in the Android interfaceReusable tokens, protected previews/widgets, local QR enrollment and selected file-transfer formats. SHA-1/SHA-256/SHA-512 and 6–8 digits are documented.
Supported file importsPlaintext Aegis, 2FAS, andOTP, Bitwarden and Ente/standard URI lists; local decryption of supported Aegis v1 and 2FAS v1–4 backups. Unsupported formats are not silently accepted.
Passwords, certificates and typed challengesSupported where the particular VPN engine and explicit profile provide the mechanism. OpenVPN/OpenConnect support typed challenge handling; select/auth-group choices must match offered options.
HOTPShared resolver/API support only. Not a completed Android token-enrollment UI; persistent counter handling is a separate requirement.
Browser SSO, push approval, WebAuthn/security keys and posture checksRequire foreground interaction or additional integration. They are not silently automated by background sync. Unknown required fields stop automation.

Linking a stored authenticator does not enroll MFA on the server or automatically make an arbitrary login compatible. Challenge attempts are limited to reduce unsafe retries. IKEv2 password/TOTP composition works only when the gateway explicitly accepts that form.

Portable token exports (URI, QR, JSON or secret text) can contain plaintext secrets, unlike the password-encrypted configuration backup. Export or copy only deliberately. This is not a claim of support for HOTP enrollment, push enrollment, Steam tokens or Google Authenticator migration payloads.

Manual sync, scheduled sync and activity history

Refresh a resource manually or configure periodic synchronization. Calendar, contacts, tasks and mail have their own scheduling paths. A resource refresh is not automatically a request to synchronize everything.

Android decides when background work runs. Connectivity, battery restrictions, expired credentials and interactive MFA can delay or stop a run. There is no guaranteed minute-by-minute schedule, continuous push service or promise of instant consistency.

The local activity history distinguishes queued, working, completed, failed and interrupted work, plus app-owned connection events. A released foreground hold is not the same as a disconnected tunnel. Detailed setup/test traces are opt-in; ordinary history remains available for troubleshooting.

Privacy-first storage and two lock choices

Android account, VPN and authenticator secrets are encrypted with AES-GCM using Android Keystore-backed keys. Sensitive app-private mail/task stores and journals also use encryption. The iOS foundation uses Keychain for credentials and platform file protection for sidecar state.

Optional settings/account-change protection gates account creation, editing, deletion, backups, VPN and authenticator configuration. It offers a password with optional strong-biometric/device-credential access. It does not prevent background synchronization. A separate whole-app lock is optional.

These are foreground access controls, not a promise that background encryption keys require a fresh biometric prompt for each sync. System Calendar and Contacts rows remain under Android’s permission and device-storage model; the app lock does not extend to other apps. VPN transport encryption is not end-to-end encryption that hides data from your own service server.

Logging is extensive about stages and outcomes, not intended to record secrets or content. Passwords, tokens, OTP seeds, private keys, message bodies and contact/event payloads must not be logged. Detailed gateway-provided text is untrusted and, when explicitly revealed, may still contain sensitive echoes. Review it before sharing. An independent security audit and broader device qualification remain outstanding.

Password-encrypted configuration backup and restore

A user-initiated Android backup contains account configurations, reusable VPN profiles, reusable TOTP registrations and credentials needed to reconstruct those accounts. The whole payload is authenticated and encrypted with a separate export password.

It does not back up calendar/contact provider rows, task data, cached mail, loaded bodies, attachments, logs, drafts, the Outbox, conflicts or pending synchronization work. It is a configuration transfer, not a full-device or mailbox backup.

The export password is not stored and cannot be recovered. Android automatic app-data backup remains disabled. Restore is validated before publication; conflicts or partial completion must be reviewed. The documentation records a limited QA-emulator round trip, not comprehensive cross-device or process-interruption qualification.

No new sync cloud account in the middle

The connection architecture does not require a sec·o·sync relay, hosted sync service or separate sec·o·sync account. Service access goes to the mail/DAV/Exchange servers and VPN gateways you choose. A service may still require its own credentials, OAuth authorization or provider registration.

“No extra account” does not mean no network services or no accounts at all: your configured providers, authentication services and app-store distribution remain separate. It also does not promise free software, lifetime free updates or a particular future licensing model.

The website itself has no analytics, third-party fonts, advertising SDKs or tracking requests. Your web host may keep access logs. This feature guide is not a replacement for the final app and website privacy notices.

How to read the connection comparison

The comparison describes routing and lifecycle responsibilities, not four mutually exclusive products. A system VPN may have per-app filtering; managed per-app VPNs can also start on demand. Apple documents network- and domain-based on-demand rules, including checks that can avoid an unnecessary tunnel.

Generic VPN routing does not usually know the semantic account or task inside a sync app. The app-specific distinction here is that a target’s policy, service probe, selected VPN, credentials and operation lifetime are coordinated in one place. Other software can implement similar orchestration; this is not a claim of exclusive invention.

The “No VPN” column assumes no active VPN. A normal sync app can nevertheless use an existing VPN’s route without special orchestration. On Android, the single active VpnService limit is per user/profile, not a ban on all process-private inner transports. Apple platforms and VPN clients have different coexistence rules. No column means unrestricted VPN nesting.

Technology and comparison references

The app-specific baseline comes from the supplied 0.3.1 implementation, service-adapter, MFA, security, design and connection-lifetime documents. Upstream sources below explain the technologies; they do not certify this app.

Back to the everyday benefits.

See how per-account connections fit into daily use.

Back to the website